What we are watching in this sector, and the research that touches it. This is the research view; the services view is on the industry page.
Whether supplier obligations were re-scoped after onboarding, or only at it.
Whether residency is evidenced per system or asserted per programme.
Whether the evidence pack exists before the request rather than after it.
Every obligation below is dated, named and externally imposed. Read them against what your organisation could evidence this week rather than against what it intends to build.
An automated cryptographic inventory and a formally approved transition plan.
That your security and cloud suppliers hold the required accreditation.
Annual penetration testing, quarterly vulnerability assessment; non-compliance means removal from procurement lists.
Demonstrated P1 coverage across IAM, patching, data protection and incident response.
Software Bill of Materials transparency for government procurement.
Programme-level AI governance aligned to emirate policy.
Documented alignment for AI deployed in public service.
Cybersecurity roles filled by qualified Saudi nationals; data localisation via NDMO.
Sector-specific AI mandates for financial institutions.
Reproduced from the Orvix Government & public sector industry page. Last reviewed 26 August 2026.
The obligation that applies here, and the artefacts most firms in this sector do not hold.
Where organisations in this sector typically sit, and the one artefact that moves them up.
Ten statements. Three minutes. Nothing submitted.
The industry page sets out what we actually do in this sector and who delivers it.